From 052390d52713e36f3e08752c2a42816fff6554e1 Mon Sep 17 00:00:00 2001 From: shyamajp <70650120+shyamajp@users.noreply.github.com> Date: Fri, 25 Feb 2022 13:58:04 +0200 Subject: [PATCH] Update GA module instructions with CSP Add instruction to load scripts from GA by modifying csp to a minimal level Signed-off-by: Shiori Yamazaki --- plugins/analytics-module-ga/README.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/plugins/analytics-module-ga/README.md b/plugins/analytics-module-ga/README.md index 92cfd7e9ae..a11243204d 100644 --- a/plugins/analytics-module-ga/README.md +++ b/plugins/analytics-module-ga/README.md @@ -47,6 +47,19 @@ app: trackingId: UA-0000000-0 ``` +4. Update CSP in your `app-config.yaml`: + +The following is the minimul content security policy required to load scripts from GA. + +```yaml +backend: + csp: + connect-src: ["'self'", 'http:', 'https:'] + # Add these two lines below + script-src: ["'self'", "'unsafe-eval'", 'https://www.google-analytics.com'] + img-src: ["'self'", 'data:', 'https://www.google-analytics.com'] +``` + ## Configuration In order to be able to analyze usage of your Backstage instance _by plugin_, we